My healthcare provider solves this by having a health portal that I log in to to send/receive messages to my doctor and view test results.
It's all SSL encrypted and protected with my individual password, which is more than they can guarantee with plain email. When I have a new message in the message center, they send me an email to tell me to log in.
I should hope that any healthcare provider that wants to share PHI with a patient does the same rather than using email, where they have no assurance that the email is encrypted, stored securely, or protected by a strong password.